The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2026-81440: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability7.3 HighN/AN/ASep 17, 2026
CVE-2026-78296: WP ManageNinja LLC FluentAuth: Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing5.3 MediumN/AN/ASep 17, 2026
CVE-2026-53679: Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.N/AN/AN/ASep 17, 2026
CVE-2026-11874: Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.N/AN/AN/ASep 17, 2026
CVE-2026-92903: Snowflake Snowflake CLI: Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be…8.2 HighN/AN/ASep 17, 2026
CVE-2026-92893: Red Hat Red Hat Satellite 6: A flaw was found in the foreman_ansible plugin's Ansible inventory API4.3 MediumN/AN/ASep 17, 2026
CVE-2026-92611: Eclipse Foundation Eclipse Ankaios: In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops…N/A4.8 MediumN/ASep 17, 2026
CVE-2026-81474: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability7.8 HighN/AN/ASep 17, 2026
CVE-2026-81439: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability3.7 LowN/AN/ASep 17, 2026
CVE-2026-81438: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic…3.7 LowN/AN/ASep 17, 2026
CVE-2026-66269: Dell: Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to…7.3 HighN/AN/ASep 17, 2026
CVE-2026-92894: Red Hat Red Hat Satellite 6: A flaw was found in the foreman_ansible plugin's Ansible override values API4.3 MediumN/AN/ASep 17, 2026
CVE-2026-78428: go neuvector: For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving…8.0 HighN/AN/ASep 17, 2026
CVE-2026-78427: go github.com/neuvector/neuvector: The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one…4.3 MediumN/AN/ASep 17, 2026
CVE-2026-78426: go neuvector: The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field3.7 LowN/AN/ASep 17, 2026
CVE-2026-78425: go github.com/neuvector/neuvector: Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a…N/A7.6 HighN/ASep 17, 2026
CVE-2026-50610: Acer System Monitoring: A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense…N/A7.4 HighN/ASep 17, 2026
CVE-2026-50609: Acer System Monitoring: A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSenseN/A7.4 HighN/ASep 17, 2026
CVE-2026-50608: Acer System Monitoring: A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSenseN/A1.2 LowN/ASep 17, 2026
CVE-2026-15688: Mitsubishi Electric Corporation: Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control…N/A9.2 CriticalN/ASep 17, 2026
CVE-2026-87831: Unknown Checkout Field Manager (Checkout Manager) for WooCommerce: The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate…4.3 MediumN/AN/ASep 17, 2026
CVE-2026-87829: Unknown Checkout Field Manager (Checkout Manager) for WooCommerce: The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate…4.3 MediumN/AN/ASep 17, 2026
CVE-2026-86320: Red Hat: A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true7.8 HighN/AN/ASep 17, 2026
CVE-2026-50607: Acer System Monitoring: A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSenseN/A2.7 LowN/ASep 17, 2026
CVE-2026-50606: Acer System Monitoring: A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSenseN/A1.2 LowN/ASep 17, 2026
1501-1525 of 509859